/us-sox-expert
Sarbanes-Oxley Act of 2002 (SOX) expert for ICFR-relevant IT and security work. Deep knowledge of 15 U.S.C. §§ 7201 et seq., §302/§404/§906 certifications, accelerated/non-accelerated filer scoping, ITGC testing across the four classic domains (Access, Change, Operations,
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill us-sox-expert --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/us-sox-expert
Context preview
The summary Claude sees to decide when to auto-load this skill.
Sarbanes-Oxley Act of 2002 (SOX) expert for ICFR-relevant IT and security work. Deep knowledge of 15 U.S.C. §§ 7201 et seq., §302/§404/§906 certifications, accelerated/non-accelerated filer scoping, ITGC testing across the four classic domains (Access, Change, Operations,
SKILL.md
us-sox-expert.SKILL.mdname: us-sox-expert
description: Sarbanes-Oxley Act of 2002 (SOX) expert for ICFR-relevant IT and security work. Deep knowledge of 15 U.S.C. §§ 7201 et seq., §302/§404/§906 certifications, accelerated/non-accelerated filer scoping, ITGC testing across the four classic domains (Access, Change, Operations, Development), entity-level controls, IT-dependent manual controls, deficiency evaluation, SOC 1 vendor reliance, and the SEC/PCAOB/DOJ enforcement triangle.
allowed-tools: Read, Glob, Grep, Write
Sarbanes-Oxley Act of 2002 (SOX) Expert
Deep, practitioner-level expertise in the Sarbanes-Oxley Act of 2002 — the U.S. federal statute that governs financial reporting controls for SEC-registrant public companies. This skill is written for the security and IT engineer who has been told they "own SOX" or "support SOX" and needs to understand what the audit machine around them actually does.
Framework identity
- **SCF framework ID**: `usa-federal-law-sox-2002`
- **Statute**: Sarbanes-Oxley Act of 2002, Public Law 107-204, codified at 15 U.S.C. §§ 7201 et seq. (criminal provisions in 18 U.S.C. §§ 1350, 1519)
- **Region**: Americas
- **Country**: US
- **Regulators**:
- **SEC** (Securities and Exchange Commission) — disclosure-rule enforcement, civil actions, criminal referrals
- **PCAOB** (Public Company Accounting Oversight Board) — created by SOX §101; oversees auditors of public companies; sets the auditing standards (notably AS 2201 — *An Audit of Internal Control over Financial Reporting that is Integrated with an Audit of Financial Statements*) that drive the way external auditors test ICFR
- **DOJ** (Department of Justice) — criminal enforcement of §802 (document destruction) and §906 (knowing false certification)
- **SCF crosswalk coverage**: only **4 SCF controls → 17 SOX-relevant controls**. That number is small for a reason — see "Why the SCF mapping is thin" below.
Framework in plain language
SOX is the U.S. response to the Enron and WorldCom accounting frauds of 2001–2002. It does **not** prescribe specific cybersecurity controls. What it does is impose three things on SEC-registrant public companies and their auditors:
1. **Personal accountability for financial disclosures** by the CEO and CFO (§302 and §906 certifications, with criminal exposure under §906). 2. **An annual management assessment of the design and operating effectiveness of Internal Controls over Financial Reporting (ICFR)** filed in the 10-K (§404(a)). 3. **An external auditor attestation on management's ICFR assessment** for accelerated filers (§404(b), required by 15 U.S.C. § 7262(b)).
The security/IT relevance is indirect but unavoidable: virtually every modern in-scope financial process depends on IT systems, so management's §404(a) assessment must cover the IT General Controls (ITGCs) protecting those systems, and the external auditor will test those ITGCs under AS 2201 as part of the §404(b) attestation. That ITGC testing is where a security or platform engineer's day-to-day SOX work happens.
Why this plugin frames SOX as a governance-over-ICFR layer
The SCF crosswalk maps only **4 SCF controls** to SOX. That is correct, not a gap — SOX's statutory text is structured around officer certifications, auditor independence, audit committee composition, document retention, and disclosure rules, not technical control objectives. The control catalog that practitioners actually test against is **COSO 2013 Internal Control — Integrated Framework** at the entity-level layer, **COBIT 5 / 2019** for IT-process controls, and the **AICPA Trust Services Criteria** where ITGC overlap exists (e.g., a SOC 1 Type II from a service organization is the typical vendor-reliance evidence).
So SOX's role in this plugin is **the governance and accountability frame**:
- §302 + §906 = personal certification (the "tone at the top" forcing function)
- §404(a) = management assessment of ICFR (forces a control inventory, scope, walkthrough, and test program)
- §404(b) = external auditor attestation (forces independent reperformance of that test program for accelerated filers)
- §802 = document retention with criminal teeth
- §409 = real-time material-event disclosure (8-K within 4 business days)
The actual control objectives flow from COSO + COBIT + the auditor's own internal control workpaper templates. This plugin helps you scope SOX correctly, run an honest ICFR-style gap assessment via the SCF crosswalk, and assemble the ITGC evidence package an external auditor will recognize — without pretending SOX is a security framework.
Territorial scope and applicability
Who must comply
Any company whose securities are **registered under §12** of the Securities Exchange Act of 1934 (listed on a U.S. national securities exchange like NYSE or Nasdaq) **or** required to file periodic reports under **§15(d)** of the 1934 Act (e.g., issuers with publicly registered debt). In short: **U.S.-listed public companies**, plus a number of issuers required to file 10-K / 10-Q / 8-K reports with the SEC even if not exchange-listed.
Foreign private issuers
A non-U.S. company with securities listed on a U.S. exchange is generally subject to SOX, with limited carve-outs and accommodation for home-country governance practices (e.g., 20-F annual filings instead of 10-K, but the §302 and §404 substance still applies). Don't assume "we're headquartered abroad" gets you out of SOX scope.
Private companies in the SOX runway
Two common cases where a private company should be running SOX-grade ICFR even though it is not yet a §12 registrant:
- **Pre-IPO (S-1 readiness)** — once the S-1 lands, the company effectively needs §404(a)-quality ICFR documentation in place; underwriters, auditors, and the SEC review team will probe it. Most pre-IPO companies start the ICFR build 12–24 months before the planned listing.
- **Acquisition by a public company** — once acquired, the target's financially significant systems becom
Read more
name: us-sox-expert description: Sarbanes-Oxley Act of 2002 (SOX) expert for ICFR-relevant IT and security work. Deep knowledge of 15 U.S.C. §§ 7201 et seq., §302/§404/§906 certifications, accelerated/non-accelerated filer scoping, ITGC testing across the four classic domains (Access, Change, Operations, Development), entity-level controls, IT-dependent manual controls, deficiency evaluation, SOC 1 vendor reliance, and the SEC/PCAOB/DOJ enforcement triangle. allowed-tools: Read, Glob, Grep, Write
Sarbanes-Oxley Act of 2002 (SOX) Expert
Deep, practitioner-level expertise in the Sarbanes-Oxley Act of 2002 — the U.S. federal statute that governs financial reporting controls for SEC-registrant public companies. This skill is written for the security and IT engineer who has been told they "own SOX" or "support SOX" and needs to understand what the audit machine around them actually does.
Framework identity
- **SCF framework ID**: `usa-federal-law-sox-2002`
- **Statute**: Sarbanes-Oxley Act of 2002, Public Law 107-204, codified at 15 U.S.C. §§ 7201 et seq. (criminal provisions in 18 U.S.C. §§ 1350, 1519)
- **Region**: Americas
- **Country**: US
- **Regulators**:
- **SEC** (Securities and Exchange Commission) — disclosure-rule enforcement, civil actions, criminal referrals
- **PCAOB** (Public Company Accounting Oversight Board) — created by SOX §101; oversees auditors of public companies; sets the auditing standards (notably AS 2201 — *An Audit of Internal Control over Financial Reporting that is Integrated with an Audit of Financial Statements*) that drive the way external auditors test ICFR
- **DOJ** (Department of Justice) — criminal enforcement of §802 (document destruction) and §906 (knowing false certification)
- **SCF crosswalk coverage**: only **4 SCF controls → 17 SOX-relevant controls**. That number is small for a reason — see "Why the SCF mapping is thin" below.
Framework in plain language
SOX is the U.S. response to the Enron and WorldCom accounting frauds of 2001–2002. It does **not** prescribe specific cybersecurity controls. What it does is impose three things on SEC-registrant public companies and their auditors:
1. **Personal accountability for financial disclosures** by the CEO and CFO (§302 and §906 certifications, with criminal exposure under §906). 2. **An annual management assessment of the design and operating effectiveness of Internal Controls over Financial Reporting (ICFR)** filed in the 10-K (§404(a)). 3. **An external auditor attestation on management's ICFR assessment** for accelerated filers (§404(b), required by 15 U.S.C. § 7262(b)).
The security/IT relevance is indirect but unavoidable: virtually every modern in-scope financial process depends on IT systems, so management's §404(a) assessment must cover the IT General Controls (ITGCs) protecting those systems, and the external auditor will test those ITGCs under AS 2201 as part of the §404(b) attestation. That ITGC testing is where a security or platform engineer's day-to-day SOX work happens.
Why this plugin frames SOX as a governance-over-ICFR layer
The SCF crosswalk maps only **4 SCF controls** to SOX. That is correct, not a gap — SOX's statutory text is structured around officer certifications, auditor independence, audit committee composition, document retention, and disclosure rules, not technical control objectives. The control catalog that practitioners actually test against is **COSO 2013 Internal Control — Integrated Framework** at the entity-level layer, **COBIT 5 / 2019** for IT-process controls, and the **AICPA Trust Services Criteria** where ITGC overlap exists (e.g., a SOC 1 Type II from a service organization is the typical vendor-reliance evidence).
So SOX's role in this plugin is **the governance and accountability frame**:
- §302 + §906 = personal certification (the "tone at the top" forcing function)
- §404(a) = management assessment of ICFR (forces a control inventory, scope, walkthrough, and test program)
- §404(b) = external auditor attestation (forces independent reperformance of that test program for accelerated filers)
- §802 = document retention with criminal teeth
- §409 = real-time material-event disclosure (8-K within 4 business days)
The actual control objectives flow from COSO + COBIT + the auditor's own internal control workpaper templates. This plugin helps you scope SOX correctly, run an honest ICFR-style gap assessment via the SCF crosswalk, and assemble the ITGC evidence package an external auditor will recognize — without pretending SOX is a security framework.
Territorial scope and applicability
Who must comply
Any company whose securities are **registered under §12** of the Securities Exchange Act of 1934 (listed on a U.S. national securities exchange like NYSE or Nasdaq) **or** required to file periodic reports under **§15(d)** of the 1934 Act (e.g., issuers with publicly registered debt). In short: **U.S.-listed public companies**, plus a number of issuers required to file 10-K / 10-Q / 8-K reports with the SEC even if not exchange-listed.
Foreign private issuers
A non-U.S. company with securities listed on a U.S. exchange is generally subject to SOX, with limited carve-outs and accommodation for home-country governance practices (e.g., 20-F annual filings instead of 10-K, but the §302 and §404 substance still applies). Don't assume "we're headquartered abroad" gets you out of SOX scope.
Private companies in the SOX runway
Two common cases where a private company should be running SOX-grade ICFR even though it is not yet a §12 registrant:
- **Pre-IPO (S-1 readiness)** — once the S-1 lands, the company effectively needs §404(a)-quality ICFR documentation in place; underwriters, auditors, and the SEC review team will probe it. Most pre-IPO companies start the ICFR build 12–24 months before the planned listing.
- **Acquisition by a public company** — once acquired, the target's financially significant systems becom
Showing the first part of this file.
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Other skills on trust-center.
- /academic-research-companion
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing, feedback, and publication. Use this skill whenever the user shares a research idea, asks to "flesh out" a topic, wants sources
Open skill - /aws-inspector-expert
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Open skill - /azure-inspector-expert
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Open skill - /crowdstrike-inspector-expert
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Open skill - /datadog-inspector-expert
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.
Open skill - /drata-inspector-expert
Interpret drata-inspector findings generated from drata-cli workflows and turn Drata control, monitor, evidence, personnel, and integration posture into GRC action.
Open skill

